Live data from Hacker News

Not paying with cash

rubenerd.com

31–40 of 259 posts

Re: Not paying with cash

#31
The article and none of the comments mention rewards yet, which are the biggest reason to use cards!

Credit card processors charge large fees on transactions, which is a huge tax on just about... everything.

You can make a lot of that tax back via rewards. And not every card user has a good rewards-paying card - it's usually the more rich that do - so rewards function as a wealth transfer from the less rich to the more rich.

Very few stores have lower prices for cash, and processors try to ban that via their contracts when they can. If you pay with cash you pay the higher price to cover the credit card fees anyway, so you're just subsidizing the rewards earners. Might as well recoup some of that yourself.

Re: Not paying with cash

#32
post #7
post #4

One thing I really love that Japan got right was the creation of e-money systems that are anonymous (you can get a Suica for 20,000 yen without any registration information), work offline (you don't need network at-payment, nor does the terminal), and are easily accessible (you can get them at any train station, you can charge them at any ATM or convenience store with cash). In contrast, a debit/credit card usually r…

> work offline (you don't need network at-payment, nor does the terminal) Surely this is massively vulnerable to double spend attacks?

My understanding here is that there's less risk of double spends here because of the extreme difficulty of cloning the smartcards involved.

So to execute the double spend you would have to find an authorized card provider, convince them to load and sign your double spend-capable program onto the smartcard (with their signature!), and then be found out within a week when reconciliation is off.

So doing a double spend will be found out, and not only will you be on a bunch of cameras doing the thing, whoever made your card will also have been compromised.

I think that in practice the "eventual" reconciliation is fairly quick nowadays. Just that the offline spend can happen quickly, and then the packet gets sent over the wire maybe a minute later rather than before the spend is approved.

Re: Not paying with cash

#33
> So why do I continue using cards? For the same reason you probably do: convenience.

Quite the opposite: when using some electronic payment method, I better make careful notes of each transaction so that I can detect whether some fraud happened (which happens for basically every method of digital payment). On the other hand, for cash this is much less necessary.

Re: Not paying with cash

#34
post #8
post #4

One thing I really love that Japan got right was the creation of e-money systems that are anonymous (you can get a Suica for 20,000 yen without any registration information), work offline (you don't need network at-payment, nor does the terminal), and are easily accessible (you can get them at any train station, you can charge them at any ATM or convenience store with cash). In contrast, a debit/credit card usually r…

I think a lot of the motivations are AML. Suica has a low maximum balance, that probably restricts the nefarious use cases.

I would personally argue that 20,000 yen is not a low maximum balance for day-to-day purchases like food, because you can recharge so easily.

Before Suica (and a bit concurrently), JNR and later JR issued "orange cards" that included both high value formats and lower value formats. The "high value" cards were 5,000 yen and 10,000 yen respectively, so the new maximum is 2x the previous "high value" orange cards that they abolished.

The real win with e-money is not getting change, in my opinion. Carrying 20,000 yen in cash is easy when it's 2x 10,000 notes, but when it's a mix including coins, it's a pain.

Re: Not paying with cash

#35
post #3

I'll always remember the time when the tourist town of Ely, Minnesota, USA had it's single fiber internet cable cut. Pretty much all the groups there trying to rent canoes, equipment, hotels, etc with corporate cards weren't able to do it. We were lucky our group brought cash. A society depending entirely on corporations for currency function is incredibly fragile in addition to corporate payment services being rent…

I remember the day I took someone on a date, only to run into a state-wide power outage.

We found a restaurant that had gas grills. They couldn't make french fries, because their fry machine was electric. They couldn't make shakes. They were pouring soda from bottles they had bought at a grocery store. They were working by candlelight and adding up the bill on a hand calculator, but they were doing business like crazy. I think they were not doing credit cards, but it was long enough ago that they might have been taking imprints. Certainly today they would not be able to take cards, unless they had battery backup or a generator, since many cards don't have the raised digits any more.

Re: Not paying with cash

#36
post #32
post #7

Earlier quoted context omitted.

> work offline (you don't need network at-payment, nor does the terminal) Surely this is massively vulnerable to double spend attacks?

My understanding here is that there's less risk of double spends here because of the extreme difficulty of cloning the smartcards involved. So to execute the double spend you would have to find an authorized card provider, convince them to load and sign your double spend-capable program onto the smartcard (with their signature!), and then be found out within a week when reconciliation is off. So doing a double spend…

> I think that in practice the "eventual" reconciliation is fairly quick nowadays. Just that the offline spend can happen quickly, and then the packet gets sent over the wire maybe a minute later rather than before the spend is approved.

This is definitely the case, and it's also "relatively instant" in the happy path. There are cases like vending machines, or during system outages where the reconciliation happens much later, but those instances are definitely becoming rarer!

Re: Not paying with cash

#37
post #7
post #4

One thing I really love that Japan got right was the creation of e-money systems that are anonymous (you can get a Suica for 20,000 yen without any registration information), work offline (you don't need network at-payment, nor does the terminal), and are easily accessible (you can get them at any train station, you can charge them at any ATM or convenience store with cash). In contrast, a debit/credit card usually r…

> work offline (you don't need network at-payment, nor does the terminal) Surely this is massively vulnerable to double spend attacks?

Not nessisarially because it can take advantage of TEEs in smart cards

Re: Not paying with cash

#38
post #4

One thing I really love that Japan got right was the creation of e-money systems that are anonymous (you can get a Suica for 20,000 yen without any registration information), work offline (you don't need network at-payment, nor does the terminal), and are easily accessible (you can get them at any train station, you can charge them at any ATM or convenience store with cash). In contrast, a debit/credit card usually r…

to me suica seemed limited (for a traveler). you could get one and charge it up with a credit card, but I don't think you could recharge it that way. You could also not get multiple ones.

I believe there is a less limited suica card you can get (not a traveler), but I think you need a japanese address.

Re: Not paying with cash

#39
post #32
post #7

Earlier quoted context omitted.

> work offline (you don't need network at-payment, nor does the terminal) Surely this is massively vulnerable to double spend attacks?

My understanding here is that there's less risk of double spends here because of the extreme difficulty of cloning the smartcards involved. So to execute the double spend you would have to find an authorized card provider, convince them to load and sign your double spend-capable program onto the smartcard (with their signature!), and then be found out within a week when reconciliation is off. So doing a double spend…

Or you can extract the secrets from a smartcard using a variety of side-channels. But the juice is rarely worth the squeeze.
Post reply on HN